ZeroHour

CVE-2026-78482

large

Local OS Command Injection in Dell Secure Connect Gateway 5.0

CVSS 3.1
7.8 high
EPSS
2%p78
Published
()
Modified
AI analysis

Dell Secure Connect Gateway (SCG) 5.0, in both its Appliance and Application forms, contains an OS command injection flaw (improper neutralization of special elements passed to operating system commands; the record's CWE tag lists CWE-89, but the described flaw type is OS command injection). An attacker who already holds low-privileged access on the SCG host, such as a local user or a limited management session, can inject special characters into a command handled by the software, causing an attacker-controlled command to execute. Successful exploitation results in command execution on the gateway host, which the CVSS scoring rates as high impact for confidentiality, integrity, and availability. Only deployments of SCG 5.0 Appliance prior to 5.36.00.16 and SCG 5.0 Application prior to 5.36.00.00 are affected by this record; other Dell products and SCG versions are not implicated. As of this entry there is no known public proof-of-concept, the flaw is not in CISA's KEV, and no exploitation in the wild has been reported.

What to do: Upgrade Dell SCG 5.0 Appliance to 5.36.00.16 or later and Dell SCG 5.0 Application to 5.36.00.00 or later; verify your currently deployed version via the SCG administration interface before patching. Because exploitation requires low-privileged local access, restrict console, SSH, and management-plane access to the SCG host or appliance to trusted administrators as an interim mitigation. With no public PoC or known exploitation, standard patch-cycle remediation is sufficient.

Affected
Dell Secure Connect Gateway 5.0 Applianceprior to 5.36.00.16
Dell Secure Connect Gateway 5.0 Applicationprior to 5.36.00.00
Estimated exposure
largetens of thousands of enterprise gateway deployments (est.; no public install counts available) — SCG is Dell's standard support-connectivity component deployed alongside large fleets of PowerEdge servers and storage systems, implying an installed base plausibly in the tens of thousands of enterprise deployments, though Dell publishes…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.

Vendors
dell
Products
secure connect gateway
Weakness
CWE-89
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.